Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.29% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Actions). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business… | |
| Aplazada | Alta (8.9) | 0.33% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Aplazada | Alta (7.7) | 0.37% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise… | |
| Aplazada | Alta (8.3) | 0.37% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence… | |
| Aplazada | Alta (7.5) | 0.39% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Pendiente de análisis | Alta (8.5) | 0.23% | — | RenovateAIMend Renovate CEAIMend Renovate EEAIMend Renovate Enterprise EditionAI | 10/9/2026 | 29/9/2026 | Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-wrapper module does not escape the distributionUrl value read from a repository's… | |
| Pendiente de análisis | Media (6.9) | 0.30% | — | RenovateAIMend Renovate CEAIMend Renovate Enterprise EditionAI | 10/9/2026 | 29/9/2026 | Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updates are not subject to the internal `minimumReleaseAge` (stability age) checks.… | |
| Pendiente de análisis | Alta (8.3) | 0.39% | — | RenovateAIMend RenovateAIMend Renovate Enterprise EditionAI | 10/9/2026 | 29/9/2026 | Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mutual TLS was incomplete. While the value of hostRules[].httpsPrivateKey was… | |
| Pendiente de análisis | Crítica (9.2) | 0.41% | — | RenovateAIMend Renovate CEAIMend Renovate EEAIMend Renovate Enterprise EditionAI | 10/9/2026 | 29/9/2026 | Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the… | |
| Pendiente de análisis | Crítica (9.2) | 0.41% | — | RenovateAIMend Renovate CEAIMend Renovate Enterprise EditionAI | 10/9/2026 | 29/9/2026 | Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials configured for that host to the URL given as the 'next' page. Because the pagination URL… | |
| Pendiente de análisis | Alta (7.7) | 0.20% | — | Tuleap Enterprise EditionAI | 25/8/2026 | 28/8/2026 | A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import. | |
| Pendiente de análisis | Media (5.3) | 0.28% | — | Oracle Java SEAIOracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAI | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise… | |
| Pendiente de análisis | Media (6.8) | 0.31% | — | Oracle Java SEAIOracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAI | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM… | |
| Pendiente de análisis | Baja (3.7) | 0.27% | — | Oracle Java SEAIOracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAI | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM… | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Tuleap Enterprise EditionAI | 13/7/2026 | 13/7/2026 | An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization. | |
| Aplazada | Baja (1.3) | 0.40% | — | Neo4j Enterprise EditionAI | 22/1/2026 | 17/6/2026 | Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by an attacker who has some legitimate access to the database. The vulnerability allows attacker without read access to a property to infer information about its value by trying to enumerate all… | |
| Aplazada | Media (4.3) | 0.33% | — | Tuleap Community EditionAITuleap Enterprise EditionAIEnalean TuleapAI | 18/9/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600… | |
| Aplazada | Media (5.5) | 0.83% | — | Kingdee Cloud Starry SKY Enterprise EditionAI | 4/8/2025 | 17/6/2026 | A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file… | |
| Aplazada | Alta (8.1) | 0.36% | — | Opennebula Community EditionAIOpennebula Enterprise EditionAI | 3/8/2025 | 17/6/2026 | OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their… | |
| Aplazada | Media (5.5) | 0.43% | — | Kingdee Cloud-starry-sky Enterprise EditionAIApache FreemarkerAI | 27/6/2025 | 17/6/2026 | A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical. Affected by this issue is the function plugin.buildMobilePopHtml of the file \k3\o2o\bos\webapp\action\DynamicForm 4 Action.class of the component Freemarker Engine. The manipulation leads to… | |
| Aplazada | Media (6.9) | 0.58% | — | Hyland Alfresco Community EditionAIHyland Alfresco Enterprise EditionAI | 18/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Aplazada | Baja (3.5) | 0.28% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Opmanager PlusAIZohocorp Manageengine Opmanager MSPAIZohocorp Manageengine Opmanager Enterprise EditionAI | 17/7/2024 | 17/6/2026 | Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module. | |
| Aplazada | Alta (8.8) | 0.46% | — | Tibco Software INC Tibco FTL Enterprise EditionAI | 12/3/2024 | 17/6/2026 | The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition: versions 6.10.1… | |
| Aplazada | Media (4.3) | 0.32% | — | Tibco Software Tibco Activespaces - Enterprise EditionAI | 12/3/2024 | 17/6/2026 | The Proxy and Client components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition contain a vulnerability that theoretically allows an Active Spaces client to passively observe data traffic to other clients. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition: versions… |